Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a8ca3df4 by Salvatore Bonaccorso at 2026-09-26T22:33:00+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -250,43 +250,43 @@ CVE-2026-100631 (Parse Server is an open source backend 
server. In versions prio
 CVE-2026-100630 (AVideo contains a stored cross-site scripting vulnerability 
in the vid ...)
        NOT-FOR-US: WWBN AVideo
 CVE-2026-100629 (Capgo (capgo.app backend) before 12.127.5 contains an 
authorization fl ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100628 (capgo.app before 12.128.12 fails to enforce an organization's 
API key  ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100627 (Capgo (Cap-go/capgo.app) server backend Supabase functions 
contain an  ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100626 (capgo through 12.128.2 contains an insecure direct object 
reference vu ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100625 (Capgo (capgo.app) exposes a native build TUS upload proxy 
(supabase/fu ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100624 (Capgo.app before 12.264.5 does not enforce upload expiry or 
build life ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100623 (Capgo (capgo.app) exposes the legacy membership table 
public.org_users ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100622 (capgo.app through 12.129.0 fails to verify deletion status 
when servin ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100621 (Capgo (capgo.app) contains an incomplete 
access-control/content-lock e ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100620 (Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected 
by an ov ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100619 (Capgo (capgo.app) blocks direct user inserts into the 
public.manifest  ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100618 (Capgo (capgo.app) is affected by an authorization flaw in the 
app icon ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100617 (Cap-go capgo.app fails to validate that principals in 
channel_permissi ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100616 (capgo.app is an over-the-air update platform for Capacitor 
apps. In al ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100615 (Cap-go capgo.app before 12.267.1 fails to validate target API 
key priv ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100614 (Capgo before 12.244.1 contains a cross-tenant integrity 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100613 (capgo.app is an over-the-air (OTA) update platform for 
Capacitor apps. ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100612 (Capgo (capgo.app) through version 12.261.0 contains an 
incomplete acce ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100611 (Capgo (capgo.app backend, versions \u2264 12.261.0) 
improperly restric ...)
-       TODO: check
+       NOT-FOR-US: Cap-go
 CVE-2026-100610 (Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id 
and PATCH ...)
        NOT-FOR-US: Flowise
 CVE-2026-100609 (Flowise (npm packages `flowise` and `flowise-components`) 
through 3.1. ...)
@@ -310,15 +310,15 @@ CVE-2026-100601 (ClawHub (openclaw/clawhub) 
application/backend contains a serve
 CVE-2026-100600 (ClawHub (the openclaw/clawhub application/backend) does not 
bind anony ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100315 (A vulnerability was detected in mathurvishal 
CloudClassroom-PHP-Projec ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100314 (A security vulnerability has been detected in mathurvishal 
CloudClassr ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100313 (A weakness has been identified in mathurvishal 
CloudClassroom-PHP-Proj ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100312 (A security flaw has been discovered in mathurvishal 
CloudClassroom-PHP ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100311 (A vulnerability was identified in mathurvishal 
CloudClassroom-PHP-Proj ...)
-       TODO: check
+       NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-XXXX [GHSA-3q6v-r5mr-hxv8: Fix quadratic-time table start detection 
on long paragraphs]
        - php-league-commonmark 2.10.3-1
        NOTE: 
https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8
@@ -545,7 +545,7 @@ CVE-2026-100546 (OpenClaw (npm package `openclaw`) versions 
>= 2026.7.2 and < 20
 CVE-2026-100545 (OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly 
enforces ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100544 (openclaw's @openclaw/voice-call package before 2026.8.1 
launches the c ...)
-       TODO: check
+       NOT-FOR-US: openclaw/voice-call
 CVE-2026-100543 (OpenClaw (npm package openclaw) before 2026.8.1 could include 
determin ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100542 (OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 
2026.8.1 ...)
@@ -569,9 +569,9 @@ CVE-2026-100534 (OpenClaw versions before 2026.8.1 contain 
an authorization bypa
 CVE-2026-100533 (OpenClaw versions before 2026.8.1 contain a path traversal 
vulnerabili ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100532 (@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp 
login to ...)
-       TODO: check
+       NOT-FOR-US: penclaw/whatsapp Node.js module
 CVE-2026-100531 (The @openclaw/slack npm package before 2026.8.1 contains an 
authorizat ...)
-       TODO: check
+       NOT-FOR-US: openclaw/slack npm package
 CVE-2026-100530 (OpenClaw versions before 2026.8.1 fail to bind working 
directory conte ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100529 (OpenClaw versions before 2026.8.1 contain an authorization 
scope widen ...)
@@ -585,15 +585,15 @@ CVE-2026-100526 (OpenClaw's Discord integration (npm 
package @openclaw/discord)
 CVE-2026-100525 (The OpenClaw Prometheus diagnostics plugin 
(@openclaw/diagnostics-prom ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-100524 (Cotonti through 1.0.0 contains a cross-site request forgery 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Cotonti CMS
 CVE-2026-100523 (Cotonti through 1.0.0 contains an open redirect vulnerability 
in messa ...)
-       TODO: check
+       NOT-FOR-US: Cotonti CMS
 CVE-2026-100522 (Cotonti through 1.0.0 contains a reflected cross-site 
scripting vulner ...)
-       TODO: check
+       NOT-FOR-US: Cotonti CMS
 CVE-2026-100521 (Cotonti through 1.0.0 contains a reflected cross-site 
scripting vulner ...)
-       TODO: check
+       NOT-FOR-US: Cotonti CMS
 CVE-2026-100520 (Laranode versions before 1.2.1 contain a path traversal 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: Laranode
 CVE-2026-100505 (Ghidra versions 11.2 through 12.1.4 contain a heap 
out-of-bounds read  ...)
        TODO: check
 CVE-2026-100504 (Ghidra versions through 12.1.4 contain a stack-based 
out-of-bounds wri ...)
@@ -601,25 +601,25 @@ CVE-2026-100504 (Ghidra versions through 12.1.4 contain a 
stack-based out-of-bou
 CVE-2026-100503 (Ghidra versions through 12.1.4 contain a heap use-after-free 
vulnerabi ...)
        TODO: check
 CVE-2026-100502 (Flame through 2.4.0 contains an insufficient session 
expiration vulner ...)
-       TODO: check
+       NOT-FOR-US: Flame
 CVE-2026-100501 (Flame through 2.4.0 contains an improper restriction of 
excessive auth ...)
-       TODO: check
+       NOT-FOR-US: Flame
 CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation 
bypass vulner ...)
        TODO: check
 CVE-2026-100418 (Flame through 2.4.0 contains an information exposure 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: Flame
 CVE-2026-100417 (RustDesk before 1.5.0 on Windows fails to enforce the one-way 
file tra ...)
-       TODO: check
+       NOT-FOR-US: RustDesk
 CVE-2026-100391 (MediaFlow Proxy through 2.4.9 contains a server-side request 
forgery v ...)
-       TODO: check
+       NOT-FOR-US: MediaFlow Proxy
 CVE-2026-100390 (Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse 
IPv6 addres ...)
-       TODO: check
+       NOT-FOR-US: Zoraxy
 CVE-2026-100389 (GestSup versions before 3.2.61 contain a remote code 
execution vulnera ...)
-       TODO: check
+       NOT-FOR-US: GestSup
 CVE-2026-100388 (RustDesk versions before 1.5.0 fail to properly validate file 
transfer ...)
-       TODO: check
+       NOT-FOR-US: RustDesk
 CVE-2026-100387 (pgPointcloud through 1.2.5 contains a heap out-of-bounds read 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: pgPointcloud
 CVE-2026-100383 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100382 (Improper Neutralization of Special Elements used in an OS 
Command ('OS ...)
@@ -637,13 +637,13 @@ CVE-2026-100377 (Exposure of Sensitive Information to an 
Unauthorized Actor vuln
 CVE-2026-100376 (Improper Neutralization of Input During Web Page Generation 
(XSS or 'C ...)
        TODO: check
 CVE-2026-100373 (OpenMetadata through 2.0.2 contains a server-side request 
forgery vuln ...)
-       TODO: check
+       NOT-FOR-US: OpenMetadata
 CVE-2026-100372 (ClipBucket v5 before 5.5.3-#197 contains a path traversal 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: ClipBucket
 CVE-2026-100369 (CliInvoke and its formerly named `AlastairLundy.CliInvoke` 
package are ...)
-       TODO: check
+       NOT-FOR-US: CliInvoke
 CVE-2026-100368 (CliInvoke is a .NET library for invoking command-line 
programs, and it ...)
-       TODO: check
+       NOT-FOR-US: CliInvoke
 CVE-2026-100310 (GNU libextractor before 1.16 loads plugins from an untrusted 
search pa ...)
        - libextractor 1:1.17-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/25/25
@@ -1290,33 +1290,33 @@ CVE-2026-13179 (The WP Maps \u2013 Google 
Maps,OpenStreetMap,Mapbox,Store Locato
 CVE-2026-12037 (The Asset CleanUp: Page Speed Booster plugin for WordPress is 
vulnerab ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-100306 (TDuck survey form through 6.0 fails to validate write 
passwords on sub ...)
-       TODO: check
+       NOT-FOR-US: TDuck survey
 CVE-2026-100305 (TDuck survey form through 6.0 fails to enforce form fill-in 
restrictio ...)
-       TODO: check
+       NOT-FOR-US: TDuck survey
 CVE-2026-100304 (TDuck survey form 6.0 contains an information disclosure 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: TDuck survey
 CVE-2026-100303 (TDuck survey form through 6.0 lacks authorization checks on 
FormThemeC ...)
-       TODO: check
+       NOT-FOR-US: TDuck survey
 CVE-2026-100248 (The Rattadan Cosmowarp smart contract before 56c6147 can have 
a compar ...)
-       TODO: check
+       NOT-FOR-US: Rattadan Cosmowarp smart contract
 CVE-2026-100237 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-100230 (Input Leap (aka input-leap) through 3.0.3, when the 
non-default --enab ...)
        TODO: check
 CVE-2026-100192 (X-SpringBoot through 6.0 exposes appKey and appSecret 
credentials in t ...)
-       TODO: check
+       NOT-FOR-US: X-SpringBoot
 CVE-2026-100190 (The AIL Framework crawler splash domain page 
(showDomain.html) is vuln ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2026-100187 (The Onion module in AIL Framework contained a performance 
shortcut in  ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2026-100177 (The AIL Framework crawler task creation API 
(api_add_crawler_task) con ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2026-100176 (The AIL Framework's username timeline feature is vulnerable 
to stored  ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2026-100174 (The AIL Framework tag selector component 
(var/www/static/js/tags.js) i ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2026-100172 (The AIL Framework (ail-project/ail-framework) contains a 
stored cross- ...)
-       TODO: check
+       NOT-FOR-US: AIL Framework
 CVE-2025-51457 (D-Link DAP-2610 up to 2.06B08r099 contains an authenticated 
command in ...)
        NOT-FOR-US: D-Link
 CVE-2025-14814 (The CSS & JavaScript Toolbox plugin for WordPress is 
vulnerable to Sto ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to